Description
WordPress Plugin Spiffy Calendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update an option. WordPress Plugin Spiffy Calendar version 4.9.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.11 or latest
References
Related Vulnerabilities
WordPress Plugin CoolClock-a Javascript Analog Clock Cross-Site Scripting (4.3.4)
WordPress Plugin Relevant-Related Posts by BestWebSoft Cross-Site Scripting (1.1.9)
Joomla! Core SQL Injection (1.7.0 - 3.9.15)
Ruby on Rails Uncontrolled Resource Consumption Vulnerability (CVE-2020-8185)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5900)